Issue metadata
Sign in to add a comment
|
Security: CVE-2017-17095 - libtiff: Heap-based buffer overflow bug in pal2rgb(pal2rgb.c) |
||||||||||||||||||||||
Issue descriptionBuffer overflow in pal2rgb, accessible via crafted input image. See http://bugzilla.maptools.org/show_bug.cgi?id=2750 adlr, chirantan: Are we using this code via cups? Assuming we do for now and setting medium severity since we sandbox cups filters IIRC.
,
Dec 4 2017
If we don't use this tool anywhere we can remove it from the OS image by adding it to the install mask like we did for tiff2pdf: https://chromium-review.googlesource.com/c/chromiumos/overlays/chromiumos-overlay/+/681074
,
Dec 5 2017
Assigning to Andrew for question in OP.
,
Dec 5 2017
Sean might also know. Sean: are we using pal2rgb?
,
Dec 5 2017
I'm days (hours?) away from paternity leave. Assigning to skau@ to triage.
,
Dec 5 2017
I don't think we're using it. I'll look at just removing it.
,
Dec 5 2017
Printing doesn't need pal2rgb. We use the tiff libraries directly.
,
Dec 6 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromiumos/overlays/chromiumos-overlay/+/b7d00816e7da7957750a2d45426f447a5a9c826b commit b7d00816e7da7957750a2d45426f447a5a9c826b Author: Sean Kau <skau@chromium.org> Date: Wed Dec 06 04:22:38 2017 chromeos/config: Mask out pal2rgb The binary is unused. Users of media-libs/tiff just use libtiff. BUG= chromium:791491 TEST=Verified we can still print images Change-Id: I7ec40315c64ee52c50480c1924993d6729eeecab Reviewed-on: https://chromium-review.googlesource.com/810064 Commit-Ready: Sean Kau <skau@chromium.org> Tested-by: Sean Kau <skau@chromium.org> Reviewed-by: Chirantan Ekbote <chirantan@chromium.org> [modify] https://crrev.com/b7d00816e7da7957750a2d45426f447a5a9c826b/chromeos/config/env/media-libs/tiff
,
Dec 6 2017
Thanks Sean!
,
Dec 7 2017
,
Mar 15 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 27 2018
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Dec 4 2017